4
CVSSv2

CVE-2020-14064

Published: 15/07/2020 Updated: 22/07/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 357
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

icewarp mail server 12.3.0.1

Github Repositories

CVE-2020-14064

CVE-2020-14064 Icewarp Email Server 12301 incorrect_access_control nvdnistgov/vuln/detail/CVE-2020-14064

CVE-2020-14064

CVE-2020-14064 Icewarp Email Server 12301 incorrect_access_control nvdnistgov/vuln/detail/CVE-2020-14064

Icewarp Email Server 12301 incorrect_access_control nvdnistgov/vuln/detail/CVE-2020-14064 Introduction : first step: Login to your account and then send request to delete whole inbox and capture this request with Burp suit (security is attacker account) second step: Sniff your local network, may be your office and find a ice warp account and its SID third step: